Emer Currie
Question:249. Deputy Emer Currie asked the Minister for Justice, Home Affairs and Migration Ireland's position on the European Commission's proposals to update the Cyber-Security Act. [70507/25]
View answerDáil Éireann Debate, Wednesday - 10 December 2025
249. Deputy Emer Currie asked the Minister for Justice, Home Affairs and Migration Ireland's position on the European Commission's proposals to update the Cyber-Security Act. [70507/25]
View answerThe EU Cybersecurity Act (CSA) came into force in the State in 2019. It is an EU Regulation that establishes a permanent mandate for the European Union Agency for Cybersecurity (ENISA) and establishes the first-ever EU-wide certification framework for Information and Communications Technology (ICT) products, services, processes and for managed security services. Its goal is to boost trust in the digital economy by ensuring a high level of cyber security and resilience across the EU.
My Department leads on giving full effect to this EU Regulation in the State and the National Cyber Security Centre is the designated National Cyber Security Certification Authority (NCCA) for the State.
Since the entry into force of the CSA in 2019, we have seen a significant expansion of the EU’s legislative framework for cyber security. ENISA’s role has grown substantially as it has been assigned new tasks under each of these legislative instruments. Therefore, our view, is that the review of the CSA needs to set out a clear mandate for ENISA’s new expanded role, ensure sufficient resources are in place to fulfil this mandate, and set the direction of how ENISA will develop in the years to come.
On the development of cyber security certification schemes which the CSA also provides for, Ireland shares the view of many other Member States that the process for creating schemes requires reform. It is clear the current process requires a thorough and comprehensive review in order to deliver certification schemes faster and in a more transparent manner with the full involvement of Member States in order to adequately support the EU’s legislative framework for cyber security, enhance compliance, reduce unnecessary administrative and cost burden on entities and strengthen resilience.
The EU Commission has started the evaluation of the CSA according to Article 67 of the Act, which provides for its evaluation and revision every two years. The Commission will, when that process concludes, prepare a report to be shared with the Member States and it will be discussed at the Horizontal Working Party on Cyber Issues (HWPCI) in the Council of the European Union. My Department in conjunction with the Department of Foreign Affairs and Trade represent Ireland at the HWPCI.
Upon receipt of the report my Department, in consultation with other relevant Departments, will review and present our views on the report through the HWPCI.